LIVE · cybersecurity feed
Live wire
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewMedusa ransomware gang has hit over 500 organizations, CISA warnsCritical RCE flaw in Windows IKE Extension now actively exploitedOracle August 2026 Critical Security Patch Update Addresses 925 CVEs
ransomware

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision. The post Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign appeared first on SecurityWeek.

zeroday.news ·

The Cl0p ransomware group has reportedly named over 40 organizations as victims in a recent campaign, specifically targeting instances of PTC Windchill. This public naming on their dark web leak site is a common tactic employed by ransomware groups to exert pressure on victims to pay the ransom, threatening to release stolen data if demands are not met.

Among the organizations reportedly listed by Cl0p are several prominent global companies, including Shell, Philips, Fiserv, Zebra Technologies, Mindray, and Largan Precision. The inclusion of such a diverse range of industries, from energy and healthcare to financial services and manufacturing, suggests a broad impact or a non-specific targeting approach that capitalized on a vulnerability in the PTC Windchill platform.

PTC Windchill is an enterprise Product Lifecycle Management (PLM) software suite used by companies to manage product data, processes, and lifecycles. It is a critical system for many organizations, often containing sensitive intellectual property, design specifications, and operational data. Compromise of such a system could lead to significant operational disruption, data theft, and potential competitive disadvantages.

While the specific vulnerability exploited in this campaign has not been detailed, ransomware attacks often leverage common initial access vectors. These can include exploiting publicly known vulnerabilities in internet-facing applications, phishing campaigns leading to credential compromise, or supply chain compromises. For enterprise software like Windchill, unpatched vulnerabilities, misconfigurations, or weak access controls are typical points of entry for sophisticated threat actors.

Mitigation strategies for this class of attack generally involve a multi-layered approach. This includes diligent patch management for all software, especially internet-facing applications and critical enterprise systems like PLM platforms. Implementing strong authentication mechanisms, such as multi-factor authentication (MFA), is crucial. Network segmentation can limit lateral movement within an environment if an initial compromise occurs. Regular security audits, employee training on phishing awareness, and robust incident response plans are also essential components of a comprehensive defense.

The reported campaign against PTC Windchill users underscores the persistent threat posed by ransomware groups to critical enterprise infrastructure. The targeting of specific software platforms highlights a potential shift towards more focused attacks that exploit vulnerabilities in widely used business applications, rather than solely relying on broad phishing campaigns. This incident serves as a reminder for organizations to maintain heightened vigilance and implement robust security practices across their entire IT estate, particularly for systems housing sensitive intellectual property and operational data.

ransomware
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

breach

Healthtech firm CareCloud data breach impacts 3.7 million patients

U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]

ai

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.